Back to advisories

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors are actively exploiting CVE-2021-35394 in Realtek Jungle SDK to deploy the Cling botnet, which uses STUN protocol traffic to hide C2 communications as legitimate NAT traversal. Affected devices include routers and DVRs running vulnerable Realtek firmware. The malware achieves persistence and can pivot to exploit additional router/DVR vulnerabilities, making it a serious risk for network compromise.

CRITICALAdvisoryOct 06, 2026
Action required
Immediately scan your network for exploitation attempts targeting CVE-2021-35394 and for STUN protocol anomalies on ports 3478-3479. Patch or isolate any Realtek-based routers and DVRs to the latest firmware version.
Affected products
Realtek Jungle SDKRealtekNozomi Networks